Show filters
249 Total Results
Displaying 221-230 of 249
Sort by:
Attacker Value
Unknown

CVE-2012-2567

Disclosure Date: May 22, 2012 (last updated October 04, 2023)
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.
0
Attacker Value
Unknown

CVE-2010-4926

Disclosure Date: October 09, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
0
Attacker Value
Unknown

CVE-2011-2903

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in tcptrack before 1.4.2 might allow attackers to execute arbitrary code via a long command line argument. NOTE: this is only a vulnerability in limited scenarios in which tcptrack is "configured as a handler for other applications." This issue might not qualify for inclusion in CVE.
0
Attacker Value
Unknown

CVE-2010-4537

Disclosure Date: January 13, 2011 (last updated October 04, 2023)
Unspecified vulnerability in CrawlTrack before 3.2.7, when a public stats page is provided, allows remote attackers to execute arbitrary PHP code via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-4994

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0
Attacker Value
Unknown

CVE-2009-4995

Disclosure Date: August 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-2078

Disclosure Date: May 25, 2010 (last updated October 04, 2023)
DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI.
0
Attacker Value
Unknown

CVE-2010-2079

Disclosure Date: May 25, 2010 (last updated October 04, 2023)
DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions, and read arbitrary files, via a trailing backslash in a URI, as demonstrated by (1) web.config\ and (2) .ascx\ files.
0
Attacker Value
Unknown

CVE-2010-2043

Disclosure Date: May 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3950

Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to newprofile.html; the (2) firstname, (3) lastname, and (4) company parameters to signup/signup.html; and the (5) firstname, (6) lastname, and (7) address[0].street1 parameters to contact.html.
0